PT-2026-64652 · Linux · Linux Kernel
CVE-2026-64431
·
Published
2026-07-25
·
Updated
2026-08-21
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds memory access occurs in the NTFS driver when
ntfs icx ib sync write() calls post write mst fixup() after ntfs ib write() returns an error. The system fails to differentiate between I/O errors and validation failures from pre write mst fixup(). Because post write mst fixup() assumes the index block contents are correct and lacks boundary checks, it can be exploited via a malicious NTFS image. Specifically, an attacker can manipulate the index block.usa ofs offset to point outside the ntfs record, set index block.usa count to 0 to cause an integer underflow, or set index block.usa count to a value larger than the actual number of sectors in the ntfs record.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel